September 23, 2026 remediation moves the deployment to Next 15.5.26 and React/React DOM 19.2.8,
with matching React renderer/types, coherent Tiptap 3.31.3 packages, PostCSS 8.5.28 and esbuild 0.28.2.
Compatible transitive updates are included. No npm audit fix --force or old Solana SDK downgrade
was used. Next's asynchronous route parameters are adapted at the framework boundary; portable
handlers retain their plain parameter-object contract.
The three critical package entries reported in the published PR's baseline audit were next,
concurrently and shell-quote (the latter two share a dependency chain, not two independent
findings). The remediation lock resolves them to Next 15.5.26, concurrently 9.2.4 and shell-quote
1.9.0 respectively; none appears in the post-remediation full audit. This reconciles the original
three-critical finding, not just the production-only audit total.
A fresh npm audit --omit=dev reports zero advisories for this lockfile. The full audit still
reports nine development-package entries (three high, six moderate), all in the legacy Solana SDK
reference-test dependency graph: @solana/web3.js, @solana/spl-token, their SPL metadata/group and
buffer helpers, bigint-buffer, jayson, stream-json, and uuid. Multiple entries can represent
one underlying advisory; package counts are not counts of distinct exploitable paths.
Those SDKs are dev dependencies of domain/shared, imported only by synthetic codec/reference
tests, not by application or worker modules. The packaged Domain runtime does not depend on them.
This is a scoped exposure assessment, not a claim that the packages have been patched or cannot
exist on disk in a build image. Do not move them into runtime dependencies or give those tests
untrusted inputs. Reassess this residual before changing their usage; npm's proposed obsolete SDK
downgrades are not an acceptable blanket fix.
The lockfile was regenerated from the 17 current workspace manifests. Retired workspace entries had survived the folder refactor and affected peer/override resolution. Boundary checks now reject such phantom workspace roots. React resolves to one installation across the monorepo; independent consumers must similarly provide a single compatible React instance.
Security overrides are present in the orchestration root and in independently runnable application manifests. npm ignores a dependency package's overrides when it is embedded in another host: a new host must carry the appropriate patched versions/overrides and audit its own installed graph. Do not infer its security status from this repository's audit.
Reproduce the audit after a clean install and rerun full framework/browser/standalone verification on the exact release head. Audit metadata changes over time; these results are a dated snapshot.